UAE PDPL for Schools: What Your IT Team Needs to Know
The UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) came into force with implementing regulations published in 2024. Like the EU GDPR, it applies to any organisation that processes personal data about individuals in the UAE — and schools process significant volumes of personal data about students, parents, staff and third parties every day. IT managers are not data protection officers, but they are responsible for a significant proportion of the technical infrastructure through which that data flows. Understanding your obligations is no longer optional.
The starting point for PDPL compliance is a data mapping exercise. You need to know what personal data your school holds, where it is stored, who has access to it, how long it is retained and what legal basis you have for processing it. For school IT teams, this means documenting every system that holds personal data: your student information system, your HR system, your CCTV system, your email platform, your cloud storage, your helpdesk system, your attendance tracking system and any third-party applications integrated with these. This is called a Record of Processing Activities (RoPA) and it is a fundamental PDPL requirement.
Data retention is an area where many schools have significant gaps. Under PDPL, personal data should not be kept for longer than necessary for the purpose for which it was collected. In practice, this means schools need defined retention schedules — how long do you keep CCTV footage? Student records after graduation? Former staff records? Email backups? The answers vary by data type and by any applicable sector-specific regulations, but the key point is that there should be a documented answer, and there should be a process for actually deleting data when retention periods expire. Data that has been forgotten about rather than deliberately deleted is a compliance risk.
Third-party processors are a significant exposure for schools. Any vendor that processes personal data on behalf of your school — your LMS provider, your cloud backup vendor, your communication platform — is a data processor under PDPL, and you are required to have a data processing agreement in place with each of them. Many vendors provide standard DPA templates; the important thing is to actually execute them and keep a record. Schools that use multiple SaaS tools for education often find they have dozens of processor relationships that were never formalised. Working through these systematically, starting with the highest-risk vendors, is the most practical approach.
Subject access and erasure rights are operational requirements that IT teams often own the technical side of. Under PDPL, individuals have the right to know what data you hold about them, to request corrections and in some circumstances to request deletion. Schools need a process for receiving these requests, identifying all data held across all systems, and responding within the required timeframe. IT managers need to understand which systems contain personal data, how to export it, and what the deletion procedures are for each. Building this capability before the first request arrives is significantly less stressful than figuring it out under a 30-day response deadline.